Hi Matt,
With Active Directory, the root DN part is not so important, it will just try to authenticate users with username@domainname.
The main thing is that the Active Directory machine must be reachable from the web server. So typically the web server would be dual homed with a network card on the public internet facing side and a network card on the local network. It would normally talk to the AD server over the local netwok as I would not think the AD machine is exposed over the internet.
So the host name must be something it can rewsolve to connect to the AD machine. You might also try using the ip address of the AD machine instead of the host name. host.domain.co.uk sounds like a public address, I would not expect that to resolve to a local lan ip address, but it would also surprise me if the AD machine was exposed over the public network so I'm thinking this is not the correct host name to contact your AD machine from the web server.
Hope it helps,
Joe